6 ms·
> is still irrelevant noise for non-users of safari Safari vends an in-app view controller used by lots of third party apps to display web content.
by objclxt 3y ago
> is still irrelevant noise for non-users of safari
Safari vends an in-app view controller used by lots of third party apps to display web content.
- Dylan16807 3y agoNot many of those show arbitrary web pages. I guess it depends on what the bug is.
- smoldesu 3y ago> Not many of those show arbitrary web pages. If I'm not mistaken, it is the renderer for many arbitrary pages like PDFs and Preview documents. Could be wrong though.
- olliej 3y ago> Not many of those show arbitrary web pages. Plenty do display arbitrary _content_ thought. Mail clients, RSS readers, various messaging (twitter, mastodon, ...) clients, etc use it. Obviously these days many apps instead just ship a 400mb out of date copy of chrome instead of using the builtin frameworks, so it's less of an addressable problem, but so it goes.
- Dylan16807 3y agoA mail client is partway there, but is probably significantly filtering the html it allows. An RSS reader would be one of those few apps that might have the full risk. Messaging platforms have to worry about unicode bugs and image bugs, but almost all html or javascript exploits don't matter to them. If there is a safari-specific problem, it's very likely they don't care about it.
- olliej 3y agoMail clients do not filter html, that's a losing strategy, they use APIs on the rendering engine they use to prevent the engine from doing anything "bad" e.g. you don't try and filter JS, you tell the engine to not enable JS, you don't try to filter urls or resources by regex on the source, you use the engine APIs to manage resource loading yourself. Then it doesn't matter what absurd syntax or encoding is being used, if the engine thinks it should do a load, or run some scripts, it asks the host app. But it doesn't matter what proportion of the app ecosystem is or is not using the system webkit framework, we both know that if Apple does update only Safari say, and then people are compromised through their RSS reader, the HN comments will be asking why Apple didn't update the system framework. Don't get me wrong - I do get annoyed at having to reboot, but I'm not sure what the better solution is given the constraints of macOS and iOS (at least iOS apps are better designed in terms of saving and restoring state).
- Dylan16807 3y ago> Mail clients do not filter html, that's a losing strategy I mean that whitelist-style, which isn't a losing strategy. But that's a side issue. I'm trying to argue that the vast majority of programs that use webkit aren't affected by the vast majority of webkit-specific bugs. > But it doesn't matter what proportion of the app ecosystem is or is not using the system webkit framework, we both know that if Apple does update only Safari say, and then people are compromised through their RSS reader, the HN comments will be asking why Apple didn't update the system framework. I'm not suggesting not to update. But yes it does matter how many programs are vulnerable.
- olliej 3y ago> I mean that whitelist-style, which isn't a losing strategy. What are you trying to filter with your "whitelist"? Anything you'd want to filter can be controlled directly via browser embedding APIs, without any vagaries or guesswork. > I'm trying to argue that the vast majority of programs that use webkit aren't affected by the vast majority of webkit-specific bugs. I'm not sure what you mean here. The whole point of a security bug is that an entity is trying to compromise the system. We aren't talking a "webkit specific rendering bug", we're talking about the goal being code execution. So "affected by" is "displays untrusted content". RSS apps, Mail apps, Messaging, and Social media apps are all subject to that. Messaging isn't arbitrarily constrained - any properly encrypted messaging system requires the client to assume that any received message is completely attacker controlled. Even in these hypothetically constrained messaging and social media apps, if nothing else, often allow you to just view web content from within the app. The goal of an attacker is to get some specific content to hit a web view. They do not necessarily care what application is driving that web view - arguably they'd prefer non-safari as 3rd party apps generally aren't sandboxed, so gaining code execution in the host is yet more powerful. > I'm not suggesting not to update. But yes it does matter how many programs are vulnerable. What matters is how many users would be exposed, which is a function of the number of apps, the number of users of all of those apps, and the degree to which those apps are exposed to arbitrary content. WebKit on macOS is widely used, and it is often (if not typically) used for untrusted content.
- pritambaral 3y agoThat still only requires a logout and login, not a full restart. In fact, it doesn't even require a logout, only restarting affected processes. I guess the software updater wasn't built to make those steps easy, so an OS reboot might've been the easiest way to ship this.
- xrisk 3y agoIIUC, safari and other essential OS components are mounted on a read-only volume. The installer has to perform special shenanigans to update it.
- flangola7 3y ago> IIUC, safari and other essential OS components are mounted on a read-only volume I... what?
- deleted 3y ago[deleted]
- pcl 3y agoIf I Understand Correctly
- olliej 3y agoAs a basic security measure the macOS system partition is readonly and cryptographically signed. https://support.apple.com/guide/security/signed-system-volume-security-secd698747c9/1/web/1 https://support.apple.com/guide/security/signed-system-volum...
- lern_too_spel 3y agoMany other systems, including ostree and Android, have solved this problem years ago. For example, the update can be installed on a read-only cryptographically signed overlay.
- zamnos 3y ago